Commit Graph
39357 Commits
Author SHA1 Message Date
Khem Raj ba6048b0ad fwupd: Only enable hsi on x86
fwupd 2.1.7 fails to configure on every non-x86 machine:

  ../sources/fwupd-2.1.7/meson.build:288:68: ERROR: Feature hsi cannot be enabled

HSI (Host Security ID) has always been implemented for x86 only, but the way
meson.build enforces that changed in 2.1.x. 2.0.19 had:

  hsi = get_option('hsi').disable_auto_if(host_machine.system() != 'linux').disable_auto_if(
    host_cpu != 'x86' and host_cpu != 'x86_64'
  ).allowed()

while 2.1.7 has:

  hsi = get_option('hsi').require(host_machine.system() == 'linux').require(
    host_cpu in ['x86', 'x86_64']
  ).allowed()

disable_auto_if() only downgrades features that are set to 'auto', so passing
-Dhsi=enabled on e.g. aarch64 used to go through silently. require() is an
assertion, so the same option is now a hard error.

The recipe lists hsi unconditionally in the default PACKAGECONFIG and therefore
always passes -Dhsi=enabled. Restrict that to the architectures whose meson
cpu_family is x86 or x86_64. Non-x86 now gets -Dhsi=disabled, and require() on
an explicitly disabled feature is a no-op rather than an error.

PACKAGECONFIG[hsi] is left alone so it can still be requested explicitly.

Verified on qemuarm64 (do_configure now succeeds, meson reports "hsi: disabled",
recipe builds through to packaging) and on qemux86-64 (hsi remains in
PACKAGECONFIG, so the feature is unchanged where it is supported).

Signed-off-by: Khem Raj <raj.khem@gmail.com>
2026-08-01 11:57:30 -07:00
Khem Raj aad68a6567 xdg-desktop-portal-wlr: upgrade 0.8.2 -> 0.8.4
Upstream changes (git log v0.8.2..v0.8.4):
 * screencast: drive the PipeWire graph ourselves; default SelectSources
   to monitors; guard xdpw_pwr_enqueue_buffer() in the PAUSED state; fix
   stream freezing on PipeWire buffer starvation; print an error message
   on the Y-invert flag.

Version-only bump (git tag v0.8.4); recipe unchanged.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:30 -07:00
Khem Raj fffa3eab75 gerbera: upgrade 3.0.0 -> 3.2.1
Upstream changes (release notes):
 * 3.1.0/3.1.1: assorted fixes and code improvements (docker startup
   under the default user, dependency maximum-version bumps).
 * 3.2.0: resolve a long-standing transcoding/error-return issue with
   libpupnp after dropping the old MediaTomb UPnP hack; allow splitting
   config.xml at any section; export/reimport web-UI entries around a
   database clear; many new import/runtime configuration entries.
 * 3.2.1: fix MySQL/PostgreSQL database migration and init with
   ffmpegthumbnailer disabled; raise supported pupnp (1.18.3) and
   jsoncpp (1.9.7) maximums.

New build dependencies in 3.2.x:
 * cxxopts is now required (find_package(cxxopts 3.2.0 REQUIRED)); add it
   to DEPENDS (provided by meta-oe).
 * A new WITH_ZIP option (default ON) pulls in libzippp and libzip for
   "package download". Neither is packaged here, so add a PACKAGECONFIG
   [zip] knob left disabled by default (-DWITH_ZIP=FALSE), matching 3.0.0
   behaviour.

The two local build patches (fmt 12 include fix, <cstring> include) still
apply and are retained.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:30 -07:00
Khem Raj 70dfb6465f srt: upgrade 1.5.4 -> 1.5.6
Upstream changes (git log v1.5.4..v1.5.6):
 * Group/bonding fixes: check value length in group config storage, fix
   deriving string options by a group, fix getting SRTO_RCVBUF/SRTO_SNDBUF
   and rejecting options not allowed on a group, and fix a wrong
   'connection lost' error when sending to a connection-pending group.
 * Fix a stalled connection that should break after rogue NAK/ACK, and a
   misleading listening-socket error message.
 * Build: Windows-on-Arm64 support, fix Windows installers, fix use of
   the OPENSSL_USE_STATIC_LIBS CMake option, deprecation warning for
   Windows+PThreads.

Drop 0002-allow-build-with-cmake-4.patch: it backported the
cmake_minimum_required(VERSION 3.5) bump, which is already present in
1.5.6 upstream.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:30 -07:00
Khem Raj 87f2c31057 tinycompress: upgrade 1.2.13 -> 1.2.16
Upstream changes (git log v1.2.13..v1.2.16):
 * 64-bit timestamp/hpointer support: compress_get_hpointer64,
   get_tstamp64 via SNDRV_COMPRESS_AVAIL64, clamp samples to UINT_MAX and
   return -ERANGE on overflow; update sound header to v0.4.0.
 * compress plugin ("mops") support: magic + compress_plugin_mops symbol
   lookup, improved hw-plugin protocol version check.
 * fcplay: decode the AAC header to set the correct codec format and fix
   next_track sequencing for gapless playback; misc fixes (include
   errno.h, avoid NULL string to printf).
 * include: install compress_ops.h as a public header.

Drop 0001-include-install-compress_ops.h-as-public-header.patch: that
change (moving compress_ops.h to nobase_include_HEADERS) was merged
upstream and is present in 1.2.16.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:29 -07:00
Khem Raj f0c9cab9e3 openal-soft: upgrade 1.24.3 -> 1.25.2
Upstream changes:
 * 1.25.x modernizes the mixer, bundles fmt 11.2.0 (was 11.1.1), and
   annotates realtime-critical functions with [[clang::nonblocking]].

Drop 0001-Add-missing-include-for-malloc-free.patch: it backported a
<cstdlib> include into the bundled fmt-11.1.1 copy, which is already
present in the fmt-11.2.0 now bundled by 1.25.2.

openal-soft hardcodes -Werror=function-effects for C++ even with
ALSOFT_WERROR=OFF. clang-22's function-effects analysis then fails the
build on calls from nonblocking mixer code into non-nonblocking
std::variant::emplace. Pre-seed HAVE_WFUNCTION_EFFECTS=OFF (clang only)
so neither -Wfunction-effects nor its -Werror promotion is added.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:29 -07:00
Khem Raj fdf95268fc nv-codec-headers: upgrade 13.0.19.0 -> 13.1.15.0
Upstream changes (git log):
 * Update headers for NVIDIA Video Codec SDK 13.1.
 * Add the full set of cuMemsetAsync-family functions and other missing
   CUDA functions for Video Codec SDK 13.1 interaction.
 * Load nvEncodeAPI.dll for native Windows ARM64.

Version-only bump (git tag n13.1.15.0); the local clean-target patch
still applies.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:29 -07:00
Khem Raj 7205920b8c fluidsynth: upgrade 2.5.3 -> 2.5.7
Upstream changes (git log v2.5.3..v2.5.7):
 * Security fixes: heap buffer overflow in the MIDI player
   (GHSA-976m-35rw-h3m6), heap overrun in the pitch_bend_range command,
   DLS ptbl/articulation integer overflows (GHSA-r4mc-v3p8-pv47,
   GHSA-hp72-35pr-6h6r), SF2 DMOD unsigned underflow (GHSA-rmc4-c8hw-455w),
   and a heap overrun for DLS samples (GHSA-59ph-rx8r-8p4j).
 * Remove systemd lock-file gating and add automatic shell port
   selection; fix big-endian cpp11 path; fix partially-uninitialized
   fluid_sample and assorted DLS 'pgal'/sample-validation fixes.

Version-only bump of SRCREV_fluidsynth; sub-source SRCREVs unchanged.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:29 -07:00
Khem Raj 1f046fc340 python3-pillow-heif: upgrade 1.1.1 -> 1.5.0
Upstream changes (release notes):
 * 1.2.0: dropped Python 3.9; PREFERRED_DECODER must be a valid decoder.
 * 1.3.0: pixel-aspect-ratio (pasp) read/write; free-threaded (no-GIL)
   Python support; fix integer overflow in the encode path leading to a
   heap OOB read (CVE-2026-28231).
 * 1.4.0: track newer bundled libheif/libde265/libx265 (not used here -
   the recipe builds against the system libraries); minimum libheif
   raised to 1.19.0.
 * 1.5.0: grid (tiled) image encoding via options.GRID_TILE_SIZE /
   tile_size, info["tiling"] read-back, and PH_LIBHEIF_CMAKE_ARGS.

Refresh 0001-setup.py-support-cross-compiling.patch for 1.5.0: setup.py
context shifted, so the patch applied with fuzz and failed the patch-fuzz
QA check. Regenerated against 1.5.0 (same STAGING_INCDIR/STAGING_LIBDIR
changes).

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:29 -07:00
Khem Raj fa672e0f91 libdvdread: upgrade 7.0.1 -> 7.1.1
Upstream changes (git log 7.0.1..7.1.1):
 * Large DVD-Audio feature addition: Audio Still Video Set (ASVS) IFO
   structures/reads, still-frame structures in ATS, ifoOpen for ASVS and
   SAMG, simultaneous CSS and CPPM decryption, stream-type logic, and
   audio_sv.vob menu exposure in DVDOpenFile.
 * DVD-VR: add and integrate IFO structures and reads.
 * Prevent library log messages from writing to stdout; add symbol
   visibility attributes for OS/2.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:29 -07:00
Khem Raj 9a5c3f43fd gupnp-tools: upgrade 0.12.2 -> 0.12.4
Upstream changes (NEWS):
 * 0.12.3: translation updates.
 * 0.12.4: bug fixes (GNOME/gupnp-tools#29) and merged MRs !7 and !8.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:28 -07:00
Khem Raj 575122a4a0 gupnp: upgrade 1.6.9 -> 1.6.10
Upstream changes (NEWS):
 * Require GSSDP >= 1.6.5 and reuse its allocated TCP socket for the web
   server.
 * Do not leak a GError in the ACL handler.
 * Fix IPv6 host-header validation.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:28 -07:00
Khem Raj 2292354019 gssdp: upgrade 1.6.4 -> 1.6.6
Upstream changes (NEWS):
 * 1.6.5: block the corresponding TCP socket when allocating a UDP socket.
 * 1.6.6: fix binding to unicast sockets (regression from 1.6.5).

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:28 -07:00
Khem Raj 4dcdd5cbff mpd: upgrade 0.24.9 -> 0.24.13
Upstream changes (NEWS):
 * 0.24.10: fix input cache deadlock; sidplay millisecond timestamps and
   libsidplayfp 3 support; allow building the upnp database plugin with
   libupnp 1.14.30 (API breakage fixed upstream).
 * 0.24.11: fix a path-traversal bug and disallow newlines in song URIs;
   curl input requires >= 7.85.0; fix a PCM decoder stack buffer overflow.
 * 0.24.12: allow empty URI in "lsinfo"/"add" (0.24.11 regression).
 * 0.24.13: number-parser range checks; curl storage drops auth probe
   requests; Opus decoder no longer adds 5 dB to header playback gain;
   limit ID3 tags to 4 MB; pipewire fd-leak fix and "media.album" tag;
   allow AF_NETLINK under systemd when UPnP is enabled.

Drop 0001-libfmt-12.2.0-support-use-fmt-format.h-not-fmt-core.h.patch:
0.24.13 already migrated the affected sources off <fmt/core.h>, and this
distro's fmt 12.2.0 still ships the <fmt/core.h> compat header, so the
patch no longer applies cleanly and is unnecessary.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:28 -07:00
Khem Raj 4b033d5349 ncmpc: upgrade 0.49 -> 0.53
Upstream changes (git log v0.49..v0.53):
 * New Interface / PageContainer abstraction; screens migrated to
   Interface::Alert() and ScreenManager::Alert(); removed the obsolete
   global "screen" and the old screen_status library.
 * FileBrowserPage now formats its prompt with libfmt; charset cleanups
   (drop Utf8ToLocaleZ).
 * TextInputDialog reworked (options struct, KEY_RETURN/LINEFEED
   forwarding in "fragile" mode, history handling).
 * Bundled fmt subproject updated (11.0.2); translation updates.

ncmpc 0.53 now formats strings with libfmt and its meson build pulls fmt
as a subproject; with wrap downloads disabled the build failed with
"Subproject fmt is buildable: NO". Add fmt to DEPENDS so the system
libfmt is used instead of the meson wrap.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:28 -07:00
Khem Raj 600204405c gst-shark: upgrade 0.8.1 -> 0.9.1
Upstream changes (git log v0.8.1..v0.9.1):
 * Add base classes to the core shark library.
 * Add an option for subclasses to disable CTF init (enabled by default).
 * Add start/stop monitoring virtual methods to the periodic tracer.
 * Move add-metadata to run after CTF initialization; use absolute paths
   in the graphics script.

0.9.1's configure.ac declares AC_INIT([GstShark], [0.9.1.1], ...) - a
nonzero "nano" component, which gst-shark's own AS_NANO/AG_GST_SET_ERROR_
CFLAGS convention treats as a git/prerelease build and therefore enables
-Werror. That turns gstinterlatency.c's use of the now-deprecated
gst_structure_{id_get,new_id,get_name_id} (superseded by *_id_str
variants in this distro's newer GStreamer core) into hard build
failures. Pass --disable-fatal-warnings to keep these as warnings, same
as a real release build would get.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:28 -07:00
Khem Raj 41619e7ac4 libsrtp: upgrade 2.7.0 -> 2.8.0
Upstream changes (CHANGES, 2.8.0):
 * Backport cryptex support to the v2 branch (#778).
 * Fix AES-192 KDF (#770).
 * Properly support the null-crypto and null-auth scenario (#760).

Version-only bump (git tag v2.8.0); recipe unchanged.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:27 -07:00
Khem Raj d98bc95961 libupnp: upgrade 1.14.25 -> 1.14.31
Upstream changes (ChangeLog):
 * 1.14.31: fix for CVE-2026-41682.
 * 1.14.30: revert an inadvertent API change (25d4bd0b).
 * 1.14.29: CMake builds from the release tarball now work.
 * 1.14.26-28: SONAME/CMake build fixes and assorted portability fixes
   (e.g. OmniOS POSIX asctime_r).

Version-only bump (git tag release-1.14.31); recipe unchanged.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:27 -07:00
Khem Raj ed7427b8b1 liblc3: upgrade 1.0.4 -> 1.1.3
Upstream changes (git log v1.0.4..v1.1.3):
 * Major new feature: LC3plus and LC3plus High-Resolution mode, including
   2.5 ms and 5 ms frame durations, asymmetric stereo frame sizes,
   half-bitrate fallback, and updated C++/Python wrappers.
 * Build: switch to a shared-object library, hidden GNU visibility and
   LTO; add a Python library wrapper.
 * Fixes: crash with NaN/infinite PCM input under fast-math; wrong gain
   offset at high-bitrate/high-resolution 48 kHz; TNS quantization
   adjustments required for LC3plus HR; conformance reports added.

Version-only bump (git tag v1.1.3); recipe unchanged and packaging
verified with the new shared library layout.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:27 -07:00
Khem Raj ca912668df libavif: upgrade 1.4.1 -> 1.4.2
Upstream changes (CHANGELOG.md, 1.4.2):
 * Require C11 for compilation (public headers remain C99).
 * avifgainmaputil: add --jobs flag for multi-threaded read/write and
   enable auto tiling; use AOM_TUNE_IQ for layered inter-frame encoding.
 * Fix memory leak of altICC on early return; avoid MT loop-restoration
   crash with libaom < 3.13.3; fix decoding of layered images with
   multiple scaled alpha layers; fix NaN bypass of AVIF_CLAMP in gain-map
   tone mapping; fix NULL deref in avifImageCopy().
 * Refreshed bundled dependency pins (aom v3.14.1, libyuv, libpng 1.6.58,
   etc.) - not used here; the recipe fetches libargparse/libyuv at their
   own pinned SRCREVs.

Version-only bump of SRCREV_libavif; sub-source SRCREVs unchanged.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:27 -07:00
Khem Raj 99ca84156d libde265: upgrade 1.0.18 -> 1.0.19
Upstream changes (release notes):
 * 1.0.19: security and edge-case correctness fixes - heap-buffer-overflow
   read in decode_slice_unit_tiles() from unvalidated PPS tile geometry
   (CVE-2026-45382) and heap OOB read in decode_slice_unit_WPP() via an
   out-of-bounds CtbAddrRStoTS access (CVE-2026-45383); dec265 SDL fixes
   for 4:4:4 streams and mid-stream resolution changes. ABI compatible
   with 1.0.18.

Not upgraded to 1.1.x: 1.1.0 reworked the x86 SIMD path to dispatch at
runtime via __builtin_cpu_supports(), which reads the compiler-rt global
__cpu_model. Under this distro's clang/lld toolchain, linking the shared
library then fails with

  R_X86_64_PC32 cannot be used against symbol '__cpu_model'; recompile with -fPIC

because clang emits a direct PC-relative access to that exported,
preemptible symbol. Building the objects -fPIC, -Bsymbolic,
--exclude-libs, -fno-direct-access-external-data and a version script
localizing __cpu_model were all tried without success (lld validates the
relocation before applying the localization). 1.0.19 stays on the
compile-time SSE path and builds cleanly, so it is the latest buildable
release here.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:27 -07:00
Khem Raj 69d615b17a aom: upgrade 3.13.1 -> 3.14.1
Upstream changes (CHANGELOG):
 * 3.14.0: significant compression-efficiency and perceptual-quality
   improvements for layered image encoding; AOM_TUNE_IQ and
   AOM_TUNE_SSIMULACRA2 now work with inter-frame (good-quality and
   realtime) modes; Variance Boost (deltaq-mode 6) extended. New
   experimental controls AV1E_SET_EXTERNAL_RATE_CONTROL and
   AV1E_GET_GOP_INFO. The in-tree "build" directory was removed and
   build/cmake moved up one level to cmake/; AOMYV12/AOMI420 img fmts
   deprecated. ABI compatible.
 * 3.14.1: bug fixes - NULL deref in validate_img() with 10-bit
   monochrome input; enlarge cx_data buffer to 2.5x uncompressed frame
   size (oss-fuzz). ABI compatible.

Drop both local patches, now upstream in 3.14.1:
 * 0001-subpel_variance_neon-Provide-prototypes-for-missing-.patch -
   3.14.1's subpel_variance_neon.c includes subpel_variance_neon.h which
   declares the previously-implicit prototypes.
 * 0001-cmake-fix-nasm-detection-w-3.0.patch - the "-hO" nasm-3.0
   detection fix is present in cmake/aom_optimization.cmake (the cmake
   dir also moved out of build/ this cycle).

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:27 -07:00
Khem Raj ce2a27d67c libmpdclient: upgrade 2.24 -> 2.26
Upstream changes (NEWS):
 * 2.26: fix a NULL pointer dereference in mpd_song_dup() (2.25
   regression).
 * 2.25: support MPD protocol 0.25 (song properties "RealUri",
   "start_ms", "end_ms"; tag "DiscSubtitle"); switch to C11; fix typos
   in MPD_STICKER_SORT_UNKNOWN.

Version-only bump (git tag v2.26); no recipe/packaging changes needed.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:27 -07:00
Khem Raj 0392f862a7 svt-av1: upgrade 4.1.0 -> 4.2.0
Upstream changes (CHANGELOG.md, 4.2.0):
 * VOD/RA: new TUNE-VMAF mode (~15% VMAF BD-rate gain), single-thread RA
   mode, RA preset/bitrate tuning for M3-M5, raw OBU output as an
   alternative to IVF, and initial_display_delay signalling to fix A/V
   sync on seek. New CLI options --cqp, --enable-intrabc, --hbd-mds,
   --enable-kf-tf.
 * RTC/low-delay: CBR rate control with Kalman-filter QP estimation,
   cyclic refresh and frame re-encode; on-the-fly MG size/preset/bitrate/
   frame-rate changes; reference-frame management API with LTR;
   --max-intra-bitrate-pct / --max-inter-bitrate-pct.
 * General: entropy-coding refactor, CDEF/MD/ME optimizations, optimized
   screen-content detection and TPL dispatch.

Version-only bump (git tag v4.2.0); no recipe/packaging changes needed.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:26 -07:00
Khem Raj 9c05bf41b8 libmodule: upgrade 5.0.1 -> 5.0.2
The only upstream change between 5.0.1 and 5.0.2 is a single commit,
"chore: bump min cmake version to 3.5.", needed for CMake 4+.

Drop 0001-Update-cmake_minimum_required-to-3.5.patch, which backported
exactly that change and is now redundant.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:26 -07:00
Khem Raj 74ef26d0ec libmatroska: upgrade 1.7.1 -> 1.7.2
Upstream changes (NEWS.md):
 * Disallow infinite sizes on all Master elements except Segment+Cluster
   and restrict KaxSeekId to 4 bytes, per RFC 9559.
 * KaxBlock releases read buffers on EndOfStream error; catch some
   internal allocation failures.
 * Deprecate KaxTrackMinCache/KaxTrackMaxCache and KaxTrackOverlay
   (per RFC 9559); add missing MatroskaChapProcessCodecID enum and
   MATROSKA_CHAPTERSKIPTYPE_INTERMISSION.
 * Fix MATROSKA_VIDEO_FIELDORDER_{TOP,BOTTOM}FIELDSWAPPED values.
 * [API break] remove MatroskaChapterTranslateCodec /
   MatroskaTrackTranslateCodec.
 * Fix includes not implicit in modern compilers; add a DEV_MODE CMake
   option and a build-configuration summary.

Drop 0001-allow-build-with-cmake-4.patch: 1.7.2 already sets
cmake_minimum_required(VERSION 3.5). LICENSE.LGPL is unchanged.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:26 -07:00
Khem Raj bf9ebecd03 libebml: upgrade 1.4.5 -> 1.4.7
Upstream changes (ChangeLog):
 * 1.4.6: mark EbmlHead as not-infinite per RFC 8794; fix leak on upper
   element found inside the last element; EbmlString::ReadFully and
   EbmlUnicodeString use std::string / automatic memory management;
   IOCallback avoids reading more than 2^32 at once; fix includes not
   implicit in modern compilers; download utfcpp automatically; add a
   DEV_MODE CMake option and a build-configuration summary.
 * 1.4.7: fix cmake rules for building with utf8cpp 4.x (upstream #344).

libebml now uses utf8cpp (utfcpp) for Unicode string handling rather
than a bundled copy: CMakeLists does find_package(utf8cpp) and otherwise
FetchContent-downloads it. Add DEPENDS = "utfcpp" (OE-core provides
utfcpp 4.1.1) so the system copy is used and the offline build resolves
utf8cpp::utf8cpp.

Drop 0001-allow-build-with-cmake-4.patch: it backported the
cmake_minimum_required(VERSION 3.5) bump that is now in 1.4.7 upstream.

Update the LICENSE.LGPL checksum for an upstream reformatting of the
license file (content still LGPL-2.1-only).

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:26 -07:00
Khem Raj d2ac54a6d0 apache-websocket: update to latest master (0ee34c7 -> 18ad4ae)
Advance the pinned SRCREV to the current tip of jchampio's master. The
latest tagged release is still 0.1.2 (already reflected in PV), and the
23 new commits are entirely test-infrastructure work: porting the test
suite from Python 2 to Python 3/asyncio/websockets and adding coverage
for the module APIs. None of them touch the module sources that get
built and installed, so the shipped mod_websocket.so is functionally
unchanged; this simply keeps the git-tracking recipe on the current tip.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:26 -07:00
Khem Raj eb4d6ede5d webmin: upgrade 2.641 -> 2.653
Upstream changes:
 * 2.650: new Systemd Services, GRUB 2, and Kea DHCP modules; WebSocket
   proxy support in Servers Index; Alpine Linux support; Let's Encrypt
   IP-based certificate support; editable SSH public keys in Users and
   Groups.
 * 2.651: Certbot certificate request/renewal fixes; fix live activation
   of Linux bond interfaces.
 * 2.652: global per-user ACL to block URL downloads from non-public IPs;
   fix hex HTML entity recognition; fix session checks with HMAC session
   keys; fix Usermin switching to use one-time login URLs.
 * 2.653: fix missing xmlrpc-lib.pl; fix partially installed Debian
   package listing; Authentic theme improvements.

Recipe changes:
 * Drop init-exclude.patch: both hunks (init/index.cgi commented-out
   runlevel loop and init/init-lib.pl exclude= support) are now
   incorporated in upstream webmin 2.653.
 * Refresh net-generic.patch: upstream added alpine-linux to the
   os_support line in net/module.info; refresh the patch context.
 * Refresh net-lib.pl.patch: context shifted by 4 lines with fuzz 1;
   refreshed against 2.653 (same fallback to debian-linux-lib.pl).
 * Remove webmin-openrc-init from do_install: webmin 2.653 ships a new
   webmin-openrc-init script that references /sbin/openrc-run, which is
   not available on systemd-based distros; remove the file to avoid an
   unresolvable RDEPENDS QA failure.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:26 -07:00
Khem Raj 53f762b750 netdata: upgrade 1.47.5 -> 2.10.4
Major version jump (1.x → 2.x series). Key upstream changes:
 * 2.x dropped the legacy Netdata Cloud Agent-Cloud-Link (ACLK) and
   merged cloud-connectivity into the main binary; ENABLE_ACLK and
   ENABLE_CLOUD cmake options removed. OpenSSL and libcurl are now
   mandatory build dependencies (no longer optional via PACKAGECONFIG).
 * Improved database engine, new collectors (systemd-units, OTel,
   scripts plugin), and expanded Go plugin with SNMP overhaul.
 * 2.10.x stabilization: fix ZFS-related crashes, eBPF shared-memory
   pool leak, SNMP counter wrapping, database engine memory safety.
 * 2.10.4: larger patch for stability, memory safety, and crash
   resilience across database engine, streaming, and collectors;
   backports new macOS hardware sensor collectors.

Recipe changes:
 * Add curl and openssl to mandatory DEPENDS (both now REQUIRED by
   cmake); remove PACKAGECONFIG[openssl] and PACKAGECONFIG[cloud].
 * Remove webui_v0/v1/v2 PACKAGECONFIG entries and associated
   do_install block (the webui architecture changed in 2.x).
 * Remove -DENABLE_ACLK=OFF from EXTRA_OECMAKE (option no longer
   exists); keep -DENABLE_EXPORTER_PROMETHEUS_REMOTE_WRITE=OFF.
 * Refresh 0002-Do-not-hardcode-systemd-unit-directories.patch for
   2.10.4 (the BUILD_FOR_PACKAGING/systemd service install blocks
   shifted ~1119 lines; same substitution preserved).
 * 2.x vendors its own libsensors copy which needs flex/bison to
   generate its config lexer/parser at build time; add flex-native
   and bison-native to DEPENDS.
 * Protobuf detection now runs unconditionally (used by several 2.x
   exporters/collectors even with the remote-write exporter disabled);
   add protobuf and protobuf-native to DEPENDS and point cmake at the
   native protoc via Protobuf_PROTOC_EXECUTABLE.
 * Disable several 2.x features that reach out to the network at
   configure time and cannot work in an offline build:
    - ENABLE_PLUGIN_OTEL / ENABLE_PLUGIN_OTEL_SIGNAL_VIEWER (pull in
      Rust/Corrosion via CMake FetchContent)
    - ENABLE_PLUGIN_SCRIPTS (requires Go, same as ENABLE_PLUGIN_GO)
    - ENABLE_ML (FetchContent-downloads dlib)
    - ENABLE_LIBBACKTRACE (ExternalProject-downloads libbacktrace)
    - ENABLE_DASHBOARD, now exposed as PACKAGECONFIG[dashboard] and
      off by default (the local agent dashboard isn't shipped in the
      release tarball; enabling it makes cmake fetch it from
      app.netdata.cloud at configure time)
 * BUILD_FOR_PACKAGING=ON now also installs sysusers.d/tmpfiles.d
   snippets under ${nonarch_libdir}; remove them in do_install since
   user creation is handled by useradd.bbclass and tmpfiles by our own
   netdata-volatiles.conf, avoiding an "installed but not shipped" QA
   failure from duplicate/unmanaged files.
 * Fix three new-in-2.x reproducibility leaks that embed host build
   paths into the packages (buildpaths QA, an error in oe-core's default
   ERROR_QA):
    - Add 0003-Do-not-record-the-configure-command-line-in-the-binar.patch:
      2.x bakes the full cmake invocation into config.h for
      "netdata -W buildinfo"; the collected flags include --sysroot= and
      -ffile-prefix-map= and so leak ${WORKDIR} into the binary.
    - Add 0004-libsensors-do-not-emit-line-directives-in-generated-s.patch:
      pass bison -l / flex -L so the generated conf-parse.[ch] and
      conf-lex.c do not carry absolute #line paths (these live in file
      contents, so -ffile-prefix-map cannot rewrite them).
    - Remove the shipped build-info-cmake-cache.gz in do_install: it is a
      gzipped CMakeCache.txt kept only for buildinfo reporting and is full
      of host paths.
   Verified with buildpaths promoted back to ERROR_QA: netdata builds and
   packages with no buildpaths diagnostics and no /home path remains
   anywhere under the package tree.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:25 -07:00
Khem Raj bc05021510 cockpit: upgrade 352 -> 364
Upstream changes (release notes):
 * 353: Networking - suggest prefix length and gateway address; bug fixes.
 * 354: Convert documentation to AsciiDoc; work around Firefox 146/147
   bug; bug fixes.
 * 355: ws - remove obsolete pam_cockpit_cert module; shell - add
   StartTransientUnit as a sudo alternative.
 * 356: systemd - allow editing timers created by Cockpit; convert
   license headers to SPDX format.
 * 357: lib - use browser context menu on shift; bridge - support
   Python 3.14 on old kernels.
 * 358: Networking - add Wi-Fi support; Cockpit Client updated to GTK 4.
 * 359: Bug fixes and translation updates.
 * 360: ws - CVE-2026-4631 (be more explicit when handling hostnames on
   cli); ws - support loading a custom login page.
 * 361: Remove all "Mount" actions in Anaconda mode; dependency updates.
 * 362: Fix arbitrary code execution via specially crafted logs page link
   (CVE-2026-4802); bug fixes.
 * 363: Translation updates.
 * 364: Bug fixes and translation updates.

cockpit 356 converted all license headers to SPDX format, moving the
LGPL-2.1 text from COPYING to LICENSES/LGPL-2.1.txt. Update
LIC_FILES_CHKSUM path accordingly (md5 is unchanged).

Refresh 0001-Warn-not-error-if-xsltproc-is-not-found.patch: the
configure.ac context shifted (-61 lines); same MSG_ERROR → MSG_WARN
change preserved.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:25 -07:00
Markus Volk 1c1a63b2a0 fluidsynth: fix branch after recipe update
- use nobranch=1
- use tag=v${PV}

Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:25 -07:00
Markus Volk f4f7c09deb colord: set proper home-dir
This fixes:
WARNING: hyprland-image-1.0-r0 do_rootfs: User colord has been defined as (colord, 998, 998, -, /home/colord, /bin/false) but sysusers.d expects it as (colord, -, -, colord colour management daemon, /var/lib/colord, -)

Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 11:57:25 -07:00
Ankur Tyagi 9b10f27d0f rygel: upgrade 45.0 -> 45.2
https://gitlab.gnome.org/GNOME/rygel/-/blob/45.2/NEWS?ref_type=tags

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 08:41:51 -07:00
Ankur Tyagi 48b523136e zenity: upgrade 4.1.99 -> 4.2.2
https://gitlab.gnome.org/GNOME/zenity/-/blob/4.2.2/NEWS?ref_type=tags

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 08:41:51 -07:00
Ankur Tyagi d548ec8b12 gnome-panel: upgrade 3.47.1 -> 3.58.1
https://gitlab.gnome.org/GNOME/gnome-panel/-/blob/3.58.1/NEWS?ref_type=tags

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 08:41:51 -07:00
Ankur Tyagi 14274de9c3 appstream-glib: upgrade 0.8.3 -> 0.8.4
New Features:
- Add symbol and sample text for Amharic and Inuktitut
- Add symbol text for N'Ko and Yi script

Bugfixes:
- Fix building the silo when shared-mime-info >= 2.5.1 is installed
- Fix RISC-V test failure

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 08:41:51 -07:00
Ankur Tyagi 573a277151 gnome-console: upgrade 47.1 -> 50.0
Dropped patch which is now merged in the upstream version.

https://gitlab.gnome.org/GNOME/console/-/blob/50.0/NEWS?ref_type=tags

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 08:41:51 -07:00
Ankur Tyagi df17223916 gnome-bluetooth: upgrade 47.1 -> 47.2
Changelog:
https://gitlab.gnome.org/GNOME/gnome-bluetooth/-/blob/47.2/NEWS?ref_type=tags

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 08:41:51 -07:00
Ankur Tyagi c07617f936 eog: upgrade 50.1 -> 50.2
Changelog:
https://gitlab.gnome.org/GNOME/eog/-/blob/50.2/NEWS?ref_type=tags

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 08:41:51 -07:00
Ankur Tyagi 918fc9d3ca imagemagick: upgrade 7.1.28 -> 7.1.29
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-08-01 08:41:50 -07:00
Ross Burton ade08ee06a xmlrpc: fix Upstream-Status
This patch has now been upstreamed.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-31 15:15:04 -07:00
Khem Raj 9dc293d14d libhtml-tree-perl, libmodule-build-tiny-perl: Drop obsolete TMPDIR scrubbing
oe-core 3c2bb7bce1 ("cpan_build: disable .packlist and html doc") moved
--create_packlist=0 into cpan_build.bbclass and disabled html doc
generation there as well. Neither .packlist nor the html docs are
generated anymore, so the do_install:append() hooks that sed'ed TMPDIR out
of them now run find(1) over paths that no longer exist and hand sed an
empty argument list:

  find: '.../image/usr/share/doc/perl/html/site/lib/HTML/': No such file or directory
  sed: no input files
  WARNING: exit code 4 from a shell command.

Remove the now dead hooks.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-31 11:03:59 -07:00
Khem Raj 8c224de973 libsdl3: Fix build with cmake 4.4
cmake's check_symbol_exists() does not forward CMAKE_REQUIRED_FLAGS to the
try_compile() it runs, unlike check_include_file() and
Internal/CheckSourceCompiles which both pass it along as
-DCOMPILE_DEFINITIONS. So the -D_GNU_SOURCE=1 that SDL adds to
CMAKE_REQUIRED_FLAGS never reaches any symbol check, and every glibc
extension hidden behind __USE_GNU is detected as missing.

HAVE_GETRESUID being unset is fatal, since SDL_gtk.c then compiles its own
static fallback which collides with the <unistd.h> declaration:

  SDL_gtk.c:90:19: error: static declaration of 'getresuid' follows
                          non-static declaration

Pass _GNU_SOURCE via CMAKE_REQUIRED_DEFINITIONS as well. This also restores
detection of memfd_create, ppoll, posix_spawn_file_actions_addchdir,
fopen64 and fseeko64, which were silently disabled.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-31 11:03:59 -07:00
Khem Raj a884b55acd oprofile: Fix build with binutils 2.47
binutils 2.47 removed the bfd_boolean compatibility define along with the
TRUE/FALSE macros it brought in, see binutils commit 1d95b744c069 ("Remove
bfd_boolean definition from bfd"). This breaks oprofile:

  opagent.c:81:2: error: use of undeclared identifier 'bfd_boolean'
  create_bfd.c:68:18: error: 'FALSE' undeclared

Add a patch using bool/false from <stdbool.h> instead, which is what the
bfd API has been returning since binutils 2.36.

Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-31 11:03:59 -07:00
Leon Anavi bfe1438fd4 python3-fastapi: Upgrade 0.140.0 -> 0.141.1
Upgrade to release 0.141.1:

- Fix support for background tasks and headers from dependencies in
  app.frontend().
- Document FASTAPI_ENV in FastAPI CLI guide.

Add DESCRIPTION and SUMMARY variables.

Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-31 11:00:10 -07:00
Leon Anavi 2cf9295bf7 python3-annotated-doc: Upgrade 0.0.4 -> 0.0.5
Upgrade to release 0.0.5:

- Drop support for Python 3.8.
- Update security policy.

Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-31 11:00:10 -07:00
Leon Anavi bdee396589 python3-unidiff: Upgrade 0.7.5 -> 1.0.0
Upgrade to release 1.0.0:

- Minimum supported Python is now 3.9 (Python 2 dropped).
- PatchedFile.path now also strips git mnemonic prefixes (c/ i/ o/
  w/ and 1/ 2/), so git diff --cached paths resolve to the plain
  filename (c/README.md -> README.md). Standard a//b/ diffs are
  unaffected.
- File modes via source_mode/target_mode + an is_symlink property.
- PatchedFile.diff_line_no to locate hunkless/binary entries.
- Accept bytes input directly (decoded with the given encoding,
  default UTF-8).
- Real PEP 484 type annotations + generics (typed iteration) and a
  py.typed marker.
- Parse difflib empty-filename output and fix a trailing-newline
  error on hunkless git format-patch files; includes the
  quoted-filename fix missing from 0.7.5
- from_filename/from_string gain metadata_only; python -m unidiff
  works; packaging on pyproject.toml with GitHub Actions CI.

Fixes:

WARNING: python3-unidiff-1.0.0-r0 do_check_backend: QA Issue:
inherits setuptools3 but has pyproject.toml with
setuptools.build_meta, use the correct class [pep517-backend]

Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-31 11:00:10 -07:00
Jason Schonberg ba40fb6ba9 php: upgrade 8.5.8 -> 8.5.9
This is a security release.

Changelog: https://www.php.net/ChangeLog-8.php#8.5.9

Signed-off-by: Jason Schonberg <schonm@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-31 00:18:32 -07:00
Leon Anavi 4103e94dc6 python3-pika: Upgrade 1.4.1 -> 1.4.2
Upgrade to release 1.4.2:

- Stop mutating global asyncio event loop policy on import
- Importing pika.adapters can break asyncio subprocesses on Windows

Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
2026-07-30 11:04:20 -07:00